Privacy Policy
What we collect, why we collect it, who it is shared with, how long it is kept, and how to make us delete it.
This Privacy Policy explains how Heirloom Journey (“Heirloom”, “we”, “us”) handles personal information when you use the Heirloom mobile application, this website and the services behind them (together, the “Service”).
Heirloom exists to hold a family’s private memories. That purpose sets the boundary for everything below: we collect what the Service needs in order to work, and nothing we would have to justify to you afterwards.
The short version
- We do not sell or rent personal information, and we never have.
- We do not serve advertising and do not share your information with advertising networks or data brokers.
- We do not use your photos, videos, audio or captions to train machine-learning models, ours or anyone else’s.
- Your memories are visible only to the people you choose. Private Vault contents are visible to nobody but you.
- You can export your content and delete your account from inside the app, without asking us for permission.
This summary is for orientation only. The sections below are the operative terms.
1. Who is responsible for your information
Heirloom Journey is the controller of the personal information described in this policy. You can reach us at privacy@heirloom.setrick.com or by post at:
Heirloom Journey
[Registered address — line 1]
[City, region, postal code]
[Country]
2. What we collect
2.1 Information you give us
| Category | What it includes | Why we need it |
|---|---|---|
| Account details | Email address and/or phone number, a display name, and a password (stored only as a one-way hash — we never hold the password itself) | To create your account, sign you in, and recover access if you lose it |
| Profile | Optional profile photo and short bio | So your family recognises you in a journey |
| Your memories | Photos, videos, voice recordings, titles, captions, dates and any comments or reactions you add | This is the content the Service exists to store and show to the people you chose |
| Private Vault | Media you place in your Vault, and a separate Vault passcode (again stored only as a one-way hash) | To keep this content locked behind a second credential, visible to nobody else |
| Family and journey structure | Which families you belong to, which journeys you are in, who you invited, and private nicknames you give other members | To enforce who can see what, and to show the right people the right content |
| Support correspondence | The content of messages you send us, and the app version and device you sent them from | To answer you and to reproduce problems |
2.2 Information collected automatically
| Category | What it includes | Why we need it |
|---|---|---|
| Session and security data | Authentication tokens, sign-in timestamps, counts of failed sign-in and failed Vault unlock attempts, and temporary lockout times | To keep you signed in and to stop somebody guessing their way into your account |
| Technical data | IP address, device model, operating system version, app version, language | To deliver the Service, diagnose faults and detect abuse |
| Activity within your circle | Which memories you have viewed (so “new” badges are accurate) and when content was added or changed | To show unread indicators and keep a journey in order |
| Push notification identifier | A device subscription identifier, if you enable notifications | To deliver the notifications you asked for |
2.3 Device permissions
The app asks for these permissions when — and only when — you use the feature that needs them. Declining a permission disables that feature and nothing else.
- Camera — to take a photo or record a video inside the app.
- Microphone — to record a voice memory.
- Photo library — to let you choose existing photos and videos to add. We receive only the files you select.
- Biometrics (Face ID, Touch ID, fingerprint) — to unlock your Vault. This is handled entirely by your device’s operating system; we receive a yes-or-no result and never your biometric data.
- Notifications — to tell you when someone adds to a journey you are in.
2.4 What we do not collect
- We do not collect precise location. The app has no location permission.
- We do not read your contacts or address book.
- We do not track you across other companies’ apps or websites.
- We do not use third-party advertising identifiers.
- We do not intentionally collect special-category data (health, biometric identifiers, religious or political beliefs). If such information appears in a photograph you upload, it is processed only as ordinary content you chose to store.
3. How we use your information
We use personal information only for these purposes:
- To provide the Service: storing your memories and showing them to the people you chose.
- To authenticate you and keep your account and Vault secure.
- To deliver the notifications you have turned on.
- To answer support requests.
- To keep the Service working and safe — diagnosing crashes, measuring aggregate reliability, detecting abuse and enforcing our Terms.
- To meet legal obligations and to establish, exercise or defend legal claims.
We do not use your content for profiling or automated decision-making that produces legal or similarly significant effects on you.
4. Legal bases (UK / EU / EEA users)
Where the UK GDPR or EU GDPR applies, we rely on the following legal bases under Article 6(1):
| Purpose | Legal basis |
|---|---|
| Providing the Service you signed up for | Performance of a contract — Art. 6(1)(b) |
| Account security, abuse prevention, service reliability | Legitimate interests — Art. 6(1)(f) |
| Push notifications; access to camera, microphone and photo library | Consent — Art. 6(1)(a), withdrawable at any time in your device settings |
| Retaining records we are required to keep | Legal obligation — Art. 6(1)(c) |
5. Who your information is shared with
We do not sell personal information. We share it only in these circumstances:
5.1 The people you choose
Content you add to a journey is visible to the members of that journey. Content in a shared vault is visible to the members of that vault. Content in your private Vault is visible to nobody but you. You control these memberships from inside the app, and you can change them at any time.
5.2 Service providers
We use a small number of processors, each bound by contract to process personal information only on our instructions and to protect it appropriately:
| Provider role | What they process |
|---|---|
| Cloud hosting and database | All Service data, at rest and in processing |
| Object storage (S3-compatible) | Your photos, videos and audio files, held in private, non-public buckets |
| Transactional email | Your email address, to send verification, password reset and support messages |
| Push notification delivery | A device subscription identifier and the notification text, if you enable notifications |
| Apple App Store / Google Play | Purchase, install and crash information governed by Apple’s and Google’s own privacy policies, not ours |
5.3 Legal and safety disclosures
We may disclose information where we are legally required to, or where it is necessary to protect the rights, property or safety of users or the public. We will notify you of a legally compelled disclosure unless we are prohibited from doing so.
5.4 Business transfers
If Heirloom is involved in a merger, acquisition or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a materially different privacy policy, and you will have the opportunity to delete your account first.
6. International transfers
Our providers may process data in countries other than your own. Where personal information is transferred out of the UK or EEA, we rely on an adequacy decision where one exists, and otherwise on Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with additional safeguards where necessary.
7. How long we keep things
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Your memories and Vault contents | Until you delete them, or until you delete your account. Content you contributed to a shared journey may remain visible to that journey’s other members — see the deletion page |
| Backups | Deleted content is purged from backups within 30 days |
| Security logs | Up to 12 months, then deleted or aggregated |
| Support correspondence | Up to 24 months after the request is resolved |
| Records we must keep by law | For the period the relevant law requires |
8. Security
We protect personal information with measures appropriate to its sensitivity, including encrypted transport (HTTPS/TLS), one-way hashing of account and Vault passwords, private object storage served through short-lived signed links, separate throttling of sign-in and Vault unlock attempts, and invalidation of every existing session when a password changes. Our Security page describes these in more detail, including what we do not claim.
No service can guarantee absolute security. If a breach affects your personal information and is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority without undue delay and, where required, within 72 hours.
9. Your rights
Depending on where you live, you may have some or all of the following rights. We honour these requests regardless of whether the law where you live compels us to.
- Access — a copy of the personal information we hold about you.
- Correction — to fix information that is inaccurate or incomplete.
- Deletion — to have your account and content erased. See Delete your data.
- Portability — a machine-readable copy of information you provided.
- Restriction and objection — to limit or object to processing based on our legitimate interests.
- Withdraw consent — at any time, without affecting processing already carried out.
- Complain — to your local supervisory authority. In the UK this is the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first.
Exercise any of these by emailing privacy@heirloom.setrick.com. We will respond within 30 days, and will tell you if we need longer because the request is complex. We will not charge you, and we will not treat you differently for asking.
9.1 California residents
Under the CCPA/CPRA you have the rights to know, delete, correct, and to opt out of the sale or sharing of personal information, and not to be discriminated against for exercising them. In the preceding twelve months we have not sold or shared personal information as those terms are defined by the CCPA, and we do not do so now. We do not knowingly sell or share the personal information of consumers under 16. The categories we collect and the purposes we collect them for are listed in sections 2 and 3 above.
10. Children
Heirloom is not directed to children under 13, and we do not knowingly collect personal information from them. Families frequently store photographs of children — that content is provided by the adult account holder, who is responsible for having the right to share it. Our Children’s Privacy page sets this out in full, including how a parent or guardian can ask us to remove a child’s information.
11. Cookies and this website
The Heirloom mobile app uses no advertising or analytics cookies. This website uses only what is strictly necessary to serve the pages you request. See the Cookie Policy.
12. Changes to this policy
We may update this policy as the Service changes. The “last updated” date at the top always reflects the current version. If a change materially affects your rights or how we use your information, we will give you notice in the app or by email before it takes effect, and where the law requires it we will ask for your consent.
13. Contact
Privacy questions and requests: privacy@heirloom.setrick.com
Anything else: support@heirloom.setrick.com